FoxVendor

FoxVendor Privacy Policy

How the FoxVendor Shopify app handles store, seller and shopper data.

Last updated:

Who we are

FoxVendor is a multi-vendor marketplace app for Shopify, built and operated by ooThemes. This policy covers the FoxVendor app itself. It does not cover the stores that install it, the sellers who trade inside them, or Shopify. You can reach us at support@oothemes.com.

Two different roles matter for reading the rest of this page:

Store data we access, and why

The app requests the permissions below at install. Each one exists because a specific feature stops working without it; the app requests no permission it does not use.

Shopify access scopes requested by FoxVendor and the feature each one supports
Permission groupScopesWhy the app needs it
Productsread_products, write_productsSellers create and edit their own listings from the vendor portal, including variants, prices and SKUs. Without write access a seller cannot publish a product at all.
Product channelsread_publications, write_publicationsWhen you approve a seller's product, the app publishes it to your Online Store channel. Reading publications is how it finds that channel; writing is how the product goes live.
Filesread_files, write_filesProduct images, seller logos and banners, and the documents a seller uploads for identity verification are stored in your Shopify Files, not on our servers.
Discountsread_discounts, write_discountsSellers can issue discount codes limited to their own products, and deactivate them again. The real discount is a Shopify discount so it applies at your checkout.
Returnsread_returns, write_returnsReturn requests are routed to the seller who shipped the items so they can approve or decline the return on their own line items.
Ordersread_ordersEach order is split into one sub-order per seller so the app can calculate that seller's subtotal, commission, tax share and payout, and reverse it when a refund is issued. Read-only on purpose: the app never edits your orders.
Locationsread_locations, write_locationsEach seller gets a dedicated Shopify location so stock and fulfillment are attributable to the seller responsible for them.
Inventoryread_inventory, write_inventoryStock a seller sets in the portal is written to that seller's own location, so two sellers listing similar items never consume each other's inventory.
Shippingread_shipping, write_shippingPer-seller shipping zones and rates are stored as Shopify delivery profiles, so a buyer is charged the rates of the seller they are actually buying from.
Merchant-managed fulfillment ordersread_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_ordersMoves each order's fulfillment work to the owning seller's location and lets that seller mark their own items fulfilled with tracking, instead of you fulfilling on their behalf.

The app also subscribes to store notifications for order creation, order fulfillment and refunds, to app uninstall, and to Shopify's three mandatory privacy notifications.

Protected customer data

Because the app reads orders, Shopify treats it as handling protected customer data. Here is exactly what that means in practice.

Order notifications

The order payload Shopify sends includes protected customer fields such as the buyer's name, email address and shipping address. From that payload the app reads only the line items, quantities, prices, discount allocations, tax lines, and the destination country and region codes it needs to attribute tax. The records it writes contain the shop domain, the seller, the Shopify order id, currency, amounts, and each line item's title, quantity and price. No customer name, email address, address or customer id is written to them.

Fulfillment and shipping labels

A seller needs the delivery address to ship the items they sold. When a seller opens one of their orders, the app fetches the shipping address from Shopify's Admin API at that moment and shows it to that seller only. It is not copied into the app's database. If the merchant has connected EasyPost, the same address plus the parcel weight is sent to EasyPost to buy a label; the app then stores the carrier, service, tracking number, cost and a link to the label. The address itself is not written to the app's database, though the label document that link points to is hosted by EasyPost and, like any shipping label, shows the delivery address. Deleting that label is subject to EasyPost's own retention.

Storefront features

Store reviews, store follows, shopper-to-seller messages and abuse reports need to know which shopper acted. That identity comes from Shopify's signed App Proxy request, which supplies a logged_in_customer_id the app can trust; it is never taken from a form field a browser could forge. For those features the app stores the customer identifier, and the content the shopper chose to submit: a display name, star rating and review text; a follow record; message text; or a report reason and description. Public pages show the display name and text, never the customer identifier.

What the app does not store about shoppers

The list below is the same list the app includes when it answers a Shopify customer data request, so a shopper gets one consistent answer.

Shopper data categories FoxVendor never stores
CategoryDetail
Payment and card detailsNo card number, bank account or payment instrument is stored for shoppers. Checkout and payment happen entirely in Shopify. The only payment references the app holds belong to sellers being paid out.
Order historyThe app keeps no shopper order archive. Its per-seller order records hold the Shopify order id and the seller's amounts, with no customer column, so an order cannot be traced back to a shopper inside the app. Order history stays in the Shopify admin.
Addresses, phone numbers and email addressesNo shipping address, billing address, phone number or email address is saved to the app's database for shoppers.
Browsing, device and analytics dataNo page views, sessions, IP addresses, device fingerprints or cookie identifiers are stored for shoppers. Sellers may configure their own analytics pixels; the app stores only the seller's pixel id, never shopper events.
Shopper account credentialsShoppers have no account or password in the app. Identity comes from Shopify's signed customer session, so there is no credential to hold.

Merchant and staff data

When the app is installed, Shopify issues it a session record. That record holds the store domain, the access token, the granted permissions and, for a logged-in staff session, the staff member's name, email address and locale as Shopify supplies them. Sessions are used to call the Shopify API on the store's behalf and are deleted when the app is uninstalled.

Seller data

Sellers are not Shopify users, so the marketplace holds their accounts. For each seller the app stores:

Third-party services

Shopify is the platform the app runs on and is always involved. Beyond Shopify, application data is held in a managed PostgreSQL database operated for the app.

Every other integration is off until the merchant turns it on by entering their own credentials in the app's settings. Because those are the merchant's own accounts, the merchant is the controller of that processing and their agreement with each provider governs it. The app does not sign a data processing agreement with a provider on the merchant's behalf, and we do not sell personal data or share it for advertising.

Optional integrations, what is sent to each, and when
ServiceWhat is sent, and only if enabled
StripeSeller payouts and seller subscription billing. The app can create a Stripe Connect account for a seller (sending their email address and country), send them to Stripe's own onboarding, and transfer an amount to that account. Stripe, not the app, collects seller identity and bank details.
PayPal PayoutsSeller payouts. The app sends the payout amount, currency and the seller's PayPal receiver email address.
EasyPostShipping labels. The app sends the buyer's delivery address, the parcel weight and the merchant's configured origin address, and receives a label and tracking number.
An AI provider chosen by the merchant: OpenAI, Anthropic, Google Gemini, or any OpenAI-compatible endpointOptional writing help for product listings. The app sends only the product text a seller is working on — title, description, keywords or tone — and receives suggested copy. No shopper, order or payout data is sent to an AI provider.
The merchant's SMTP mail serverNotification email, and the document the app produces when Shopify forwards a customer data request. Recipient address and message content pass through the mail server the merchant configured.
Endpoints the merchant registers for outbound notificationsMarketplace events such as an order being created or a payout being paid, sent to a URL the merchant chose and signed with a shared secret so the receiver can verify them.

How long data is kept, and how it is deleted

The app acts on all three of Shopify's mandatory privacy notifications. This is what each one does.

When the app is uninstalled

The app deletes the store's stored Shopify sessions, including the access token, and clears its cached plan. It stops being able to call the store. Marketplace records are deliberately kept at this point, so an accidental uninstall followed by a reinstall does not destroy a working marketplace.

Store data deletion

Shopify sends a shop redaction request roughly 48 hours after uninstall. On receiving it the app deletes the store's sellers and everything linked to them — products, sub-orders and their line items, ledger entries, payouts, follows, reviews, coupons, shipping profiles and rates, verifications, conversations and messages, abuse reports, staff accounts, connected external stores and their tokens, shipment labels, badges, pixels, wholesale rules and offers — together with the store's marketplace settings and the integration credentials stored in them, seller subscription plans, tax rates, API keys, registered outbound endpoints, any remaining sessions, and its record of processed notifications.

Shopper data deletion

On a customer redaction request the app deletes that shopper's store follows, store reviews, and conversations with sellers including every message in them. Abuse reports are handled differently on purpose: the report is kept as a safety record for the merchant, but the link to the shopper who filed it is removed so the report can no longer be traced back to them.

Shopper data requests

On a customer data request the app gathers everything it holds for that shopper in that store — follows, reviews, conversations with their full message text, and reports — and builds a document that also names the categories it never stores, so the answer is complete either way. It emails that document to the store owner's Shopify contact address. Shopify requires the store owner to forward it to the shopper within 30 days. The app keeps no copy of the document, and never writes it to a log. Delivery depends on the merchant having configured a mail server; when one is missing the app records that the merchant must send the data another way.

Security

These are the controls the app implements. We make no security certification claim — for example SOC 2 or ISO 27001 — and none should be inferred. No system can be guaranteed completely secure.

Your rights

Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, and to object to or restrict its processing. How to exercise those rights depends on who holds your data:

We answer requests sent to support@oothemes.com within 30 days. We may need to route a request to the merchant who controls the data, and we will say so if that happens.

International transfers

The app and the services it can be connected to operate internationally, so data may be processed outside the country where it was collected, including in the United States. Each provider publishes its own terms for those transfers, and the merchant's agreement with any provider they enabled governs them.

Children

FoxVendor is a business tool for merchants and the sellers who trade in their stores. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child's data has reached us, write to support@oothemes.com and we will remove it.

Changes to this policy

When the app's data handling changes, we update this page and the date at the top. The version published here is always the current one, so it is worth re-reading after a significant app update.

Contact

Privacy questions, data requests and security reports all go to support@oothemes.com. This page describes how the app works; it is not legal advice, and merchants remain responsible for their own store's privacy notice.